Rated
Jul 25 2007
•
1 review
•
security, tests, hips
• lycos.fr
More interesting tests by NicM. This time seven malware that are known for "unhooking" abilities (a new breed of malware designed to beat HIPS) are tested against some HIPS.
" These malwares are then very dangerous, not only because they can bypass programs that are supposed to block them, but because once they're installed, nothing abnormal is showing on the system protected by an HIPS which was bypassed : If the HIPS was killed, the program interface is still showing its status as 'OK', 'running', leaving the user in a false sense of security (thinking he is protected, although he isn't)."
A short summary of results
1st : ProSecurity 1.30 7/7 - Excellent
2nd & 3rd tie : AntiHook 3.0 and Online Armor 2 6.5/7 - Very Good
4th : Dynamic Security Agent 3.5/7 - Average
5th-7th tie : EQSecure 3.3, Process Guard 3.410 and System Safety Monitor 2.4.0 3/7 - Poor
8th : Prevx 2 2.5/7 - Poor
9th : CyberHawk 2.0.4 1.5/7 - Very Poor
10thth : Primary Response SafeConnect 2.1 > 0 on 7 > None
My comment: Poor results with cyberhawk, Prevx,Primary response were expected. On the other end good results with ProSecurity was as well.
Disappointed with results with SSM,EQsecure. We already knew DSA was not bad in prior test.
Curious about other tests on HIPs? See
here